# Liability — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/aansprakelijkheid
> Sources are cited per item. Verify against the official texts before relying on them.

Legal responsibility for GDPR violations and damages

## Overview

## Legal Framework

Article 82 GDPR establishes the right to compensation and the liability framework for GDPR violations. Controllers are liable for damage caused by processing that infringes the Regulation, while processors face liability only for damage resulting from their failure to comply with processor-specific obligations or from acting outside or contrary to lawful controller instructions. Both controllers and processors are exempt from liability if they demonstrate they were not in any way responsible for the event giving rise to damage — placing the burden of proof on the defendant rather than the claimant for the question of responsibility.

Recital 85 underscores that personal data breaches can produce physical, material, or non-material damage, including loss of control over personal data, identity theft, reputational harm, and financial loss. This broad conception of damage is central to the compensation regime: Article 82(1) explicitly covers both material and non-material damage, and Recital 146 confirms that data subjects need not suffer material harm to qualify for compensation.

The liability regime interacts with the substantive obligations in Article 6 (lawful basis), Articles 15–17 (data subject rights), and Article 28 (processor contracts). A breach of any of these provisions can trigger Article 82 liability if it causes compensable damage. Article 29 reinforces processor accountability by requiring that processors and their personnel process personal data only on the controller's documented instructions.

## Key Developments

Dutch courts have begun setting practical thresholds for non-material damage claims under Article 82. In the Rechtbank Amsterdam decision (C/13/677172 / HA RK 19-435), the court rejected a claim for €500 in non-material damage based on loss of control over personal data, finding the claimant had insufficiently substantiated how the loss of control actually caused harm. The court also noted that, unlike prior cases where compensation was awarded, the defendant had not disclosed the claimant's data to third parties. This signals that bare assertions of lost control are inadequate; claimants must demonstrate a concrete nexus between the infringement and the harm suffered.

The CJEU's reasoning in *Rijkeboer* (C-553/07) remains relevant for liability analysis: disproportionate retention limitations that prevent data subjects from exercising access rights can themselves constitute an infringement capable of generating damage. The *Nikolaou* line of authority on non-contractual EU liability is instructive on evidentiary burdens — while the general rule places the burden on the applicant, that burden shifts to the institution where multiple causes could explain the damage and the institution fails to provide exculpatory evidence.

Enforcement actions by DPAs further illustrate the financial exposure. The Icelandic DPA fined Reykjanesbær municipality €16,600 and the City of Reykjavik €13,300 for inadequate safeguards when deploying Google Education systems — demonstrating that insufficient diligence in processor selection and assessment translates directly into administrative fines and potential civil liability.

## Practical Guidance

- **Document every lawful basis decision under Article 6 with a proportionality assessment** — particularly for legitimate interests and public task bases, which carry the broadest discretion and the highest risk of challenge. Courts will scrutinize whether the balancing test was genuinely performed.

- **Ensure processor contracts under Article 28(3)(a) explicitly restrict processing to documented instructions** — this creates the contractual and statutory parallel required by Article 29 and defines the boundary of processor liability under Article 82(2).

- **Maintain evidence of data breach detection, notification, and remediation** — Recital 85 makes clear that failure to address breaches promptly aggravates liability; demonstrable timely response is a key defense against claims for both material and non-material damage.

- **Substantiate non-material damage claims with specificity** — the Amsterdam court's rejection of generic "loss of control" claims means that data subjects must articulate concrete harm, while controllers can defend by showing no third-party disclosure occurred and no demonstrable adverse consequence resulted.

- **Prepare for burden-shifting scenarios** — following *Nikolaou*, where multiple causes could explain damage, controllers and processors should proactively gather and present evidence isolating the cause, as failure to do so shifts the evidentiary burden against them.

## Legislation (full text of key provisions)

### Right to compensation and liability

*Source: GDPR, gdpr-art-82-en, 2016-04-27 — https://overview.legal/posts/91364*

### Recital 23 — service provider control liability exemption exception

*Source: DSA, dsa-rec-23-en, 2022-10-19 — https://overview.legal/posts/95443*

The exemption of liability should not apply where the recipient of the service is acting under the authority or the control of the provider of a hosting service. For example, where the provider of an online platform that allows consumers to conclude distance contracts with traders determines the price of the goods or services offered by the trader, it could be considered that the trader acts under the authority or control of that online platform.

### Recital 18 — Active role liability exemption exclusion

*Source: DSA, dsa-rec-18-en, 2022-10-19 — https://overview.legal/posts/95433*

The exemptions from liability established in this Regulation should not apply where, instead of confining itself to providing the services neutrally by a merely technical and automatic processing of the information provided by the recipient of the service, the provider of intermediary services plays an active role of such a kind as to give it knowledge of, or control over, that information. Those exemptions should accordingly not be available in respect of liability relating to information provided not by the recipient of the service but by the provider of the intermediary service itself, including where the information has been developed under the editorial responsibility of that provider.

### Recital 26 — voluntary moderation liability exemption good faith

*Source: DSA, dsa-rec-26-en, 2022-10-19 — https://overview.legal/posts/95449*

In order to create legal certainty, and not to discourage activities that aim to detect, identify and act against illegal content that providers of all categories of intermediary services undertake on a voluntary basis, it should be clarified that the mere fact that providers undertake such activities does not render unavailable the exemptions from liability set out in this Regulation, provided those activities are carried out in good faith and in a diligent manner. The condition of acting in good faith and in a diligent manner should include acting in an objective, non-discriminatory and proportionate manner, with due regard to the rights and legitimate interests of all parties involved, and providing the necessary safeguards against unjustified removal of legal content, in accordance with the objective and requirements of this Regulation. To that aim, the providers concerned should, for example, take reasonable measures to ensure that, where automated tools are used to conduct such activities, the relevant technology is sufficiently reliable to limit to the maximum extent possible the rate of errors. In addition, it is appropriate to clarify that the mere fact that the providers take measures, in good faith, to comply with the requirements of Union law, including those set out in this Regulation as regards the implementation of their terms and conditions, should not render unavailable the exemptions from liability set out in this Regulation. Therefore, any such activities and measures that a provider may have taken should not be taken into account when determining whether the provider can rely on an exemption from liability, in particular as regards whether the provider provides its service neutrally and can therefore fall within the scope of the relevant provision, without this rule however implying that the provider can necessarily rely thereon. Voluntary actions should not be used to circumvent the obligations of providers of intermediary services under this Regulation.

### Recital 127 — minimum enforcement powers and proportionate penalties

*Source: NIS2, nis2-rec-127-en, 2022-12-14 — https://overview.legal/posts/96782*

In order to make enforcement effective, a minimum list of enforcement powers that can be exercised for breach of the cybersecurity risk-management measures and reporting obligations provided for in this Directive should be laid down, setting up a clear and consistent framework for such enforcement across the Union. Due regard should be given to the nature, gravity and duration of the infringement of this Directive, the material or non-material damage caused, whether the infringement was intentional or negligent, actions taken to prevent or mitigate the material or non-material damage, the degree of responsibility or any relevant previous infringements, the degree of cooperation with the competent authority and any other aggravating or mitigating factor. The enforcement measures, including administrative fines, should be proportionate and their imposition should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

### Recital 101 — multiple-stage significant incident reporting

*Source: NIS2, nis2-rec-101-en, 2022-12-14 — https://overview.legal/posts/96730*

This Directive lays down a multiple-stage approach to the reporting of significant incidents in order to strike the right balance between, on the one hand, swift reporting that helps mitigate the potential spread of significant incidents and allows essential and important entities to seek assistance, and, on the other, in-depth reporting that draws valuable lessons from individual incidents and improves over time the cyber resilience of individual entities and entire sectors. In that regard, this Directive should include the reporting of incidents that, based on an initial assessment carried out by the entity concerned, could cause severe operational disruption of the services or financial loss for that entity or affect other natural or legal persons by causing considerable material or non-material damage. Such initial assessment should take into account, inter alia, the affected network and information systems, in particular their importance in the provision of the entity’s services, the severity and technical characteristics of a cyber threat and any underlying vulnerabilities that are being exploited as well as the entity’s experience with similar incidents. Indicators such as the extent to which the functioning of the service is affected, the duration of an incident or the number of affected recipients of services could play an important role in identifying whether the operational disruption of the service is severe.

### Recital 83 — data security risk assessment and mitigation

*Source: GDPR, gdpr-rec-83-en, 2016-04-27 — https://overview.legal/posts/91681*

In order to maintain security and to prevent processing in infringement of this Regulation, the controller or processor should evaluate the risks inherent in the processing and implement measures to mitigate those risks, such as encryption. Those measures should ensure an appropriate level of security, including confidentiality, taking into account the state of the art and the costs of implementation in relation to the risks and the nature of the personal data to be protected. In assessing data security risk, consideration should be given to the risks that are presented by personal data processing, such as accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed which may in particular lead to physical, material or non-material damage.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

### Recital 75 — personal data processing risks to individuals

*Source: GDPR, gdpr-rec-75-en, 2016-04-27 — https://overview.legal/posts/91665*

The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from personal data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage; where data subjects might be deprived of their rights and freedoms or prevented from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, and the processing of genetic data, data concerning health or data concerning sex life or criminal convictions and offences or related security measures; where personal aspects are evaluated, in particular analysing or predicting aspects concerning performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements, in order to create or use personal profiles; where personal data of vulnerable natural persons, in particular of children, are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.

### Recital 133 — temporary suspensions and prohibitions as enforcement

*Source: NIS2, nis2-rec-133-en, 2022-12-14 — https://overview.legal/posts/96794*

In order to further strengthen the effectiveness and dissuasiveness of the enforcement measures applicable to infringements of this Directive, the competent authorities should be empowered to suspend temporarily or to request the temporary suspension of a certification or authorisation concerning part or all of the relevant services provided or activities carried out by an essential entity and request the imposition of a temporary prohibition of the exercise of managerial functions by any natural person discharging managerial responsibilities at chief executive officer or legal representative level. Given their severity and impact on the entities’ activities and ultimately on users, such temporary suspensions or prohibitions should only be applied proportionally to the severity of the infringement and taking account of the circumstances of each individual case, including whether the infringement was intentional or negligent, and any actions taken to prevent or mitigate the material or non-material damage. Such temporary suspensions or prohibitions should only be applied as a last resort, namely only after the other relevant enforcement measures laid down in this Directive have been exhausted, and only until the entity concerned takes the necessary action to remedy the deficiencies or comply with the requirements of the competent authority for which such temporary suspensions or prohibitions were applied. The imposition of such temporary suspensions or prohibitions should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

## Case law

### Bulgarian SAC upholds lawfulness of criminal record checks for bank legal counsel role

*Source: Supreme Administrative Court of Bulgaria‎, 2026-07-30 — https://overview.legal/posts/187486 — original: https://gdprhub.eu/index.php?title=BAC_(Bulgaria)_-_8426/2026*

Facts — The data subject was a candidate for the position of senior legal counsel at the Bulgarian branch of the German commercial bank Flatex Degiro (the controller). As a prerequisite for entering into an employment relationship, the controller required her to submit a criminal record certificate. The data subject brought a damages claim before the Administrative Court of Sofia, seeking BGN 100 in compensation for non-material damage. She argued that the requirement to provide a criminal record certificate was unlawful and that the processing of the personal data contained in it lacked a legal basis. She alleged that this caused her psychological distress, discomfort and stress in the workplace. The controller argued that the requirement was justified by the nature of the position and the access to confidential information associated with it. It maintained that the unauthorised use of such information could lead to fraud and abuse. The Administrative Court dismissed the claim after finding that the processing of the data subject’s criminal record certificate was lawful under Article 6(1)(c) GDPR. It found that the applicable Bulgarian anti-money laundering legislation did not expressly provide for requesting a criminal record certificate at the time but rejected a formalistic approach requiring an explicit legal provision. It considered that the requirement followed from the purpose and overall framework of the anti-money laundering legislation and therefore found the processing lawful under Article 6(1)(c) GDPR. The data subject appealed this decision before the Bulgarian Supreme Administrative Court. Holding — The Bulgarian Supreme Administrative Court first noted that an Article 82 GDPR damages claim requires three cumulative conditions: an infringement of the GDPR, damage and a causal link between the infringement and the damage. It also held that the controller bore the burden of proving the lawfulness of the processing pursuant to Article 82(2) GDPR. It found that it had provided sufficient evidence that the processing was lawful. The court however did not base the lawfulness of the processing on a legal obligation under Article 6(1)(c) GDPR. The court agreed that requiring and reviewing the criminal record certificate constituted processing of personal data but found that the processing was lawful under Article 6(1)(f) GDPR. It considered that the controller had a legitimate interest in assessing the reliability of a senior legal counsel who would have access to confidential information, including client data, contracts, corporate documents and correspondence with banks and regulatory authorities. The court also considered the risk that such information could be misused for fraud or other abuses. The court found no infringement of the GDPR and upheld the dismissal of the damages claim. It further observed that the emotional distress alleged by the data subject appeared to result not from the processing of her personal data itself, but from the controller’s failure to accept her professional opinion that requesting the criminal record certificate was unlawful.

### CA - EWCA Civ 899 Vince v. Associated Newspapers Limited

*Source: Court of Appeal, 2026-07-15 — https://overview.legal/posts/144030 — original: https://gdprhub.eu/index.php?title=CA_-_EWCA_Civ_899_Vince_v._Associated_Newspapers_Limited*

Facts — Associated Newspapers Limited, the controller, published print and online articles in the Daily Mail and Mail+ on 8 and 9 June 2023 concerning a data subject. The articles were published under the headline "Labour repays £100,000 to 'sex harassment' donor" and featured two photographs of the data subject immediately beneath the headline. The article explained that the Labour donor accused of sexual harassment was another person, not the data subject. However, the data subject argued that the juxtaposition of the headline and his photographs created the misleading impression that he was the person referred to in the headline. The photographs were later removed from the online version of the article, but remained in the print edition. The data subject first brought defamation proceedings against the controller. The High Court struck out the claim, holding that a libel claim must be assessed by reference to the publication as a whole and that the article made clear that the allegations concerned another person. The data subject also complained to the Independent Press Standards Organisation, which rejected the complaint. The data subject subsequently brought a claim under Article 5(1)(a) and Article 82 UK GDPR, alleging that the controller had processed his personal data unfairly by juxtaposing his photographs with the headline. The High Court struck out the claim as an abuse of process and, in any event, granted summary judgement in favour of the controller, holding that the personal data had been processed fairly when the publication was considered as a whole. The data subject appealed both findings. Holding — The Court allowed the appeal. It held that the High Court had erred in striking out the claim as an abuse of process and in granting summary judgement in favour of the controller. Instead, it dismissed the application to strike out the claim and granted summary judgement to the data subject on liability, with damages to be assessed. The Court held that the controller had processed the data subject's personal data unfairly in breach of Article 5(1)(a) UK GDPR. It found that the juxtaposition of the headline referring to a "sex harassment donor" with photographs of the data subject was misleading and likely to lead readers to believe that the headline referred to him. Although the body of the article clarified that another individual was the subject of the allegations, many readers would only see the headline and photographs. The Court rejected the controller's argument that the fairness of the processing should be assessed by applying the common law principle that publications must be read as a whole. It held that this principle did not determine whether processing was fair under Article 5(1)(a) UK GDPR. Instead, fairness had to be assessed in light of the context of the processing. In reaching its conclusion, the Court relied on the Editors' Code of Practice, which requires newspapers to take care not to publish misleading information or images, including headlines not supported by the text. It found that the controller had failed to take adequate care to avoid publishing misleading information and could not rely on the journalism exemption under the Data Protection Act 2018. Finally, the Court held that, as the controller had accepted that the data subject had suffered material damage, the data subject was entitled to summary judgement under Article 82 UK GDPR, with damages to be assessed.

### CJEU - C-526/24 - Brillen Rottler

*Source: GDPRhub, C-526/24, 2026-07-13 — https://overview.legal/posts/96819 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-526/24_-_Brillen_Rottler*

Facts — On 16 March 2023, the data subject (a private individual living in Vienna) subscribed to the ‘newsletter’ on the website of the controller (a family run optician company established in North Rhine-Westphalia) by entering his personal data in the registration form, confirming his consent to data processing by ticking a box and submitting the form. On 29 March 2023, the data subject sent by fax an information request pursuant to Article 15 GDPR. The controller acknowledged receipt of the request and stated that it would respond to it within the one-month period. However, by letter of 26 April 2023, the controller refused to provide the information since it classified the information request as an abuse of right for the purposes of the second sentence of Article 12(5)(b) GDPR. The controller sought a declaration from the referring court that the data subject is not entitled to compensation in the amount of €1000. The court decided to refer the following questions set out in point I. to the CJEU for a preliminary ruling pursuant to Article 267 TFEU: Is the second sentence of Article 12(5) GDPR to be interpreted as meaning there cannot be an excessive information request from the data subject when the first request is made to the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that the controller can refuse an information request from the data subject if the data subject intends to use the information request to provoke claims for damages against the controller? Is the second sentence of Article 12(5) GDPR to be interpreted as meaning that grounds for refusing to provide information can be provided by publicly available information about the data subject which suggests that the data subject is asserting claims for damages against the controller in a large number of cases of infringement of the law relating to the protection of personal data? Is Article 4(2) GDPR to be interpreted as meaning that an information request from a data subject to the controller pursuant to Article 15(1) GDPR and/or a response to that request constitutes processing within the meaning of Article 4(2) GDPR? In view of the first sentence of recital 146 GDPR, is Article 82(1) GDPR to be interpreted as meaning that only damage which the data subject suffers or has suffered as a result of processing is eligible for compensation? Does this mean that for there to be a claim for damages under Article 82(1) GDPR – assuming causal damage to the data subject exists – there must necessarily have been processing of the data subject’s personal data? If the answer to Question 5 is in the affirmative: Does this mean that the data subject – assuming causal damage exists – has no claim for compensation under Article 82(1) GDPR solely on the basis of an infringement of his or her right to information under Article 15(1) GDPR? Is Article 82(1) GDPR to be interpreted as meaning that the controller’s objection relating to an abuse of right in relation to an information request from the data subject cannot, in view of EU law, consist in the fact that the data subject brought about processing of his or her personal data solely or inter alia in order to assert claims for damages? If the answers to Questions 5 and 6 are in the negative: Does the mere loss of control and/or uncertainty about the processing of the data subject’s personal data associated with an infringement of Article 15(1) GDPR constitute non-material damage to the data subject within the meaning of Article 82(1) GDPR or does it also require a further (objective or subjective) restriction and/or (significant) damage to the data subject? Advocate General Opinion — In addressing the first, second, third, and seventh questions referred by the national court: — The excessive character of an initial access request Advocate General emphasized that while an initial access request can, in theory, be considered "excessive," this must be limited to exceptional circumstances since the right of access is fundamental and linked to other GDPR rights. The circumstances that allow a request to be characterized as ‘excessive’ The Advocate General analyzed when a data access request under Article 15 GDPR could be considered excessive under Article 12(5) GDPR . He concluded that such a request may only be treated as excessive if the controller can demonstrate an abusive intention. However, merely having a pattern of making similar claims in many cases does not, on its own, prove abuse, and strict criteria must be applied to ensure that the fundamental right of access is not unduly restricted. In addressing the the fourth, fifth and sixth questions referred by the national court : — The event giving rise to the damage within the meaning of Article 82 of the GDPR The Advocate General analyzed whether only data processing that violates the GDPR can give rise to compensation under Article 82 GDPR. He concluded that not just unlawful processing, but any infringement of the GDPR can be a basis for compensation, provided that damage and a causal link are proven. The concept of ‘processing’ for the purposes of the right to compensation The Advocate General explains that although sending an access request is not "processing" under the GDPR, a controller’s act of responding to such personal data , which can fall under the scope of the GDPR. However, the actual damage arises not from this technical processing, but from the unjustified refusal to fulfill the access request. To ensure the effectiveness of Article 15 GDPR and the right to compensation under Article 82, the concept of “processing that caused the damage” should be interpreted broadly. The existence of non-material damage The Advocate General clarifies that a violation of Article 15 GDPR alone does not automatically entitle a data subject to compensation; the individual must prove actual non-material harm resulting from the infringement. The Court has recognized that even temporary loss of control over personal data may qualify as non-material damage, without requiring a minimum severity threshold. Conclusion — In the Advocate General’s view, an initial access request under Article 15 GDPR can only be considered “excessive” where the data controller can clearly demonstrate, based on all relevant circumstances, that the data subject acted with abusive intent, specifically, where the individual consented to the processing of their personal data solely to submit an access request and subsequently claim compensation. Importantly, the mere fact that a data subject has frequently exercised their right to compensation in similar cases does not, in itself, justify classifying the request as excessive. Moreover, under Article 82(1) GDPR, a data subject is entitled to compensation for damage resulting from a violation of the Regulation, even if that damage was not directly caused by the processing of personal data. Holding — Is a first access request excessive in accordance with Article 12(5) GDPR, and under what circumstances is it possible to establish such an excessive nature? (Questions 1, 2, 3 and 7) — The court first noted that the GDPR guarantees the right to access in Article 15(1) GDPR. However, Article 12(5) GDPR allows the controller to charge a reasonable fee or refuse the request if it is “manifestly unfounded or excessive”. Given the fact that the GDPR does not define these terms, the concept must be understood through its wording and objectives pursued . The court stated that Article 12(5) GDPR does not rule out the possibility that a first request may be considered excessive. This is because the repetitive character referred to in this article is an example, meaning “excessive” is not necessarily limited to the number of requests. However, this must be interpreted strictly; therefore, the controller may only rely on this in exceptional cases, and the controller bears the burden of demonstrating the excessive nature of the request. In terms of circumstances, the court noted that proof of an abusive practice must meet objective and subjective requirements. The court noted that the data subject’s access request met the formal requirements, as the data subject exercised the right to access to be aware of the processing and verify its lawfulness in accordance with the aim of Article 15 GDPR. The subjective element, on the other hand, concerns the intention of the data subject; in this case the controller must unequivocally demonstrate that the data subject has made the request for a purpose other than being aware of the processing and verifying its lawfulness (such as artificially creating conditions to obtain compensation). The court stated that it is necessary to take into consideration all the circumstances of the case, including the fact that the data subject provided the data voluntarily, or the time elapsed between providing the data and requesting access. The court noted that the controller may use publicly available information, provided that it is supported by other material. The court concluded that it was for the referring court to determine whether the controller demonstrated that the data subject made the access request with abusive intentions. Does Article 82(1) confer the right to compensation for damages resulting from an infringement of the right to access? (questions 5 and 6) — The court first noted that under Article 82(1) GDPR data subjects that have suffered (non)material damages as a result of an infringement of the GDPR are entitled to compensation. Since the Article does not refer to “processing”, the right to compensation is not limited to damage resulting from the processing of personal data. In this case, an infringement is liable for damages from the refusal to act, rather than from the actual processing of personal data as such. The court also noted that the right of access would be significantly weakened if Article 82(1) GDPR was limited solely to unlawful acts involving data processing. In light of the answer to these questions, the court saw no need to answer question 4. Does non-material damage for data subjects include loss of control or uncertainty over how their data is processed? (question 8) — The court noted that the GDPR does not define “(non)material damages” or “compensation for damages suffered”. Therefore, they must be considered autonomous concepts of EU law, and interpreted in a uniform manner . The court referred to previous case law, and highlighted the fact that “non material damage” cannot be limited by the degree of seriousness. However, an infringement on its own does not give data subjects the right to compensation, as it is one of the three conditions that must be met cumulatively. Therefore, the data subject must also establish that the infringement caused them harm, and that there is a causal link between the damage and the infringement. This applies to loss of control, as well as data subjects’ fears regarding the misuse of their data. Finally, the court stated that the causal link may be broken by the behaviour of the data subject; this means a data subject may not receive compensation for damages when the loss of control or fears over misuse of data were caused by the data subject submitting this data to the controller with the aim of artificially creating conditions to obtain compensation).

### AG Arnsberg - 42 C 434/23

*Source: Local Court Arnsberg, 2026-07-01 — https://overview.legal/posts/90173 — original: https://gdprhub.eu/index.php?title=AG_Arnsberg_-_42_C_434/23*

Facts — An Austrian citizen residing in Vienna (the data subject) subscribed to the newsletter of a family-run optician company (the controller) mainly operating in the German states of North Rhine-Westphalia and Lower Saxony in March 2023. During the registration process, he provided his email address as well as his first and last name and consented to the processing of his personal data. He then made an access request under Article 15 GDPR by fax, using letterhead that included his full home address, email address, and fax number. The controller refused to provide the requested information in April 2023 as it considered the request to constitute abuse of rights. It cited newspaper reports indicating that the defendant had subscribed to numerous newsletters solely for the purpose of asserting claims for damages. The controller brought proceedings concerning the legality of its rejection of the access request. The data subject demanded access to the information required by in Article 15 GDPR and the payment of monetary compensation of €1,000 in a counter-lawsuit. The court referred the case to the CJEU for a preliminary ruling in July 2024. The CJEU rendered its judgment in the case C-526/24 Brillen Rottler on 19 March 2026. It held that even an initial access request could be rejected on the grounds of an abuse of rights. According to the CJEU, the assessment of abusive conduct is based on all circumstances of the individual case. Both objective circumstances and the subjective intent of the data subject need to be taken into account. An abusive intent always exists if the access request is made in order to artificially create a claim for damages. Holding — The court held that the lawsuit had originally been well-founded and ruled that the counterclaims were without merit. According to the court, the controller could reject the data subject’s access request as excessive under Article 12(5)(b) GDPR. The data subject also had no right to damages under Article 82 GDPR due to the absence of a GDPR violation. The court referred to the preliminary ruling in the case C-526/24 and based its decision on an overall assessment of the objective and subjective circumstances of the present case as required by the CJEU decision. It held that the data subject’s conduct had been abusive. To the conviction of the court, there were numerous indications of abusive conduct: first, the data subject had voluntarily disclosed more personal data than was needed to subscribe to the newsletter. Second, the court could not identify any personal interest in a regional newsletter concerning operations in Nordrhein-Westfalen, as the data subject was an Austrian resident. In addition, the court took into account that the data subject had made the access request only nine days after subscribing to the newsletter and had not filed a complaint with the competent DPA before raising a claim for damages. Finally, information on the internet about numerous cease-and-desist letters sent by the data subject pointed to abusive conduct.

### OLG München - 36 U 1054/25 e

*Source: Higher Regional Court Munich, 2026-06-26 — https://overview.legal/posts/184545 — original: https://gdprhub.eu/index.php?title=OLG_München_-_36_U_1054/25_e*

Facts — The data subject had used a social media platform operated by the controller, an Irish company, since 2013. The controller provided “Business Tools” to third-party website operators and app providers. These tools enabled the controller to obtain data concerning how users interacted with third-party websites and apps, including information about page visits, purchases and advertisements clicked. In November 2023, the data subject requested that the controller recognize that the processing of his personal data was contrary to the parties’ contract, erase or anonymize the personal data, provide access to the personal data and pay compensation. The data subject subsequently brought an action before the Regional Court of Munich II, seeking a declaration that the parties’ user contract did not permit the processing, cessation of the processing of personal data collected through the Business Tools on third-party websites and apps, restriction of further processing, erasure or anonymization of previously collected data and at least €5,000 in non-material damages. The relevant data included direct and indirect identifiers, such as his name, contact details, IP address and internal identifiers, as well as website URLs, visit times, app names and information about his interactions with websites and apps. The Regional Court of Munich II dismissed the action, holding that the declaratory and erasure or anonymization claims were inadmissible, the cessation claims were legally unavailable and the damages claim had not been sufficiently substantiated. In relation to the damages claim, it found that the data subject had not identified specific third-party websites or apps through which his personal data had been processed. The data subject accordingly appealed to the Higher Regional Court of Munich. Holding — The Higher Regional Court of Munich partially upheld the appeal. First, the court held that the Controller processed the data subject’s personal data under Articles 4(1) and 4(2) GDPR by receiving data transmitted through its Business Tools, associating it with a user account and storing it. The data subject was not required to identify every website, app or individual transmission because the relevant information was principally within the controller’s knowledge and it was sufficiently probable that he had been affected. Second, referring to CJEU C‑40/17 concerning the broad interpretation of “controller”, the court held that the controller was a joint controller under Articles 4(7) and 26 GDPR for the collection and transmission of the personal data. It controlled the programming of the Business Tools and participated in determining the purposes and means of processing. Allocating certain obligations to third-party website and app operators did not remove its responsibility. Third, referring to CJEU C‑252/21, the court held that the controller had not established a lawful basis for the processing of the personal data. The processing was not justified by consent under Article 6(1)(a), contractual necessity under Article 6(1)(b), a legal obligation under Article 6(1)(c), a public-interest task under Article 6(1)(e), or legitimate interests under Article 6(1)(f) GDPR. Accordingly, the court held that the controller's processing infringed Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. Relying on CJEU C‑655/23, the court granted an injunction against future unlawful processing under German law. It also ordered restriction pending erasure under Article 18(1)(b) and erasure under Article 17(1)(d) GDPR. The court upheld the dismissal of the separate declaratory claim and also rejected anonymization of the website and app interaction data. Finally, relying on BGH VI ZR 10/24, the court awarded €1,500 in non-material damages under Article 82(1) GDPR for the data subject’s loss of control over his personal data.

### BGH awards non-material GDPR damages for erroneous disclosure of applicant salary data

*Source: Federal Court of Justice, 2026-06-23 — https://overview.legal/posts/184554 — original: https://gdprhub.eu/index.php?title=BGH_-_VI_ZR_97/22*

Facts — An employee of a private bank (the controller) erroneously sent a third party a message that was intended for a candidate in the controller’s staff selection process (the data subject) in October 2018. The message contained the data subject’s full name and information about their salary expectations. After the data subject was informed they were no longer considered for the position, they brought court proceedings requesting injunctive relief in order to prohibit the controller from processing the data subject’s personal data in connection with their job application. In addition, the data subject claimed non-material damages. The court of first instance granted the injunction and awarded the data subject € 1,000 in damages. The appellate court upheld the injunction but rejected the damages claim. The Federal Court of Justice (BGH) referred several questions to the CJEU regarding the interpretation of Article 82 GDPR. The CJEU rendered its judgment in the case C-655/23 Quirin Privatbank in September 2025. It held that Member States may provide for injunctive relief in national law in cases of unlawful processing. According to the CJEU, negative feelings caused by a loss of control over personal data can also constitute non-pecuniary damages. Holding — First, the Federal Court of Justice held that the data subject was entitled to non-material damages in accordance with Article 82 GDPR. The court confirmed the appellate court had correctly found that sending the message containing personal data to a third party had been unlawful due to the lack of a legal basis under Article 6(1) GDPR – the data subject had not consented to the processing. Furthermore, the controller had not argued that the processing would have been lawful under a different legal basis. The court also confirmed that the data subject had suffered non-material damage as a result of this GDPR violation. In the present case, the data subject’s concern that the recipient of the message might use the personal data contained in it for their own job applications already constituted loss of control of the data subject’s personal data and was therefore enough to establish a claim for damages under Article 82 GDPR. The court referred the case back to the appellate court so that it could determine the amount of non-material damages. Finally, the court held that the appellate court had erroneously upheld the data subject’s claim for injunctive relief: there was no risk of recurrence required for such a claim in German law. As the staff selection process in which the data subject had participated had already been completed, there was no likelihood whatsoever that such an infringement of the data subject’s rights would recur.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### German Supreme Court: No GDPR basis for debt transmission to credit agency; €500 damages

*Source: German Supreme Court, 2026-05-12 — https://overview.legal/posts/53895 — original: https://gdprhub.eu/index.php?title=BGH_-_VI_ZR_375/2*

Facts — A debt collection agency (the controller) sent reminders to a customer (the data subject) for delayed installment payments related to a terminated electricity contract in November 2019. The data subject considered the claimed sums to be excessive and refused to pay. The controller transmitted the information on outstanding debts of €795 and €817 to a credit information agency, which in turn made negative entries in its database. This lowered the credit score assigned to the data subject by the credit information agency. The data subject sued the controller for disclosing outstanding receivables to the credit information agency. The court of first instance ordered the controller to revoke the negative entries contained in the credit ranking database and awarded the data subject €500 in damages. The controller appealed this decision. The appellate court held that there had been no legal basis for the transmission of personal data, as the data subject had not consented to the processing and the requirements for legitimate interests pursuant to Article 6(1)(f) GDPR were not met. However, the court considered that the data subject had not suffered any non-material damage within the meaning of Article 82 GDPR. The controller appealed the case further to the Federal Court of Justice. Holding — The Federal Court of Justice dismissed the controller’s appeal and referred the case back to the appellate court. First, the court held transmitting the personal data to the credit information agency had been unlawful due to the lack of a legal basis. It pointed out that the requirements for processing based on legitimate interests laid down in Article 6(1)(f) GDPR were not met. As such, legitimate public interests in preventing the granting of credit to those who are unable or unwilling to pay could justify the transfer of data to credit information agencies. However, no meaningful indications regarding the data subject’s ability or willingness to pay could be derived from the credit information entries at issue: the controller had failed to demonstrate the debts existed in the amount claimed. Therefore, it could not rely on legitimate interests as a legal basis. Second, the court held that the data subject was entitled to the revocation of the disputed credit information entries due to the unlawful disclosure of their personal data. According to the court, this claim could be based on 1) the application of Article 19 GDPR in conjunction with Article 17(1) (d) GDPR, 2) Article 19 GDPR in conjunction with Articles 5(1)(a), 5(2), and 24(1) GDPR, or 3) national law by analogy. Third, the court held that the data subject had suffered non-material damage within the meaning of Article 82 GDPR due to the harm caused to their economic reputation. The fact that the credit reports adversely affected the data subject’s credit score, which could then be taken into account by potential contractual partners, was enough to give rise to a claim for damages. The court pointed out that the transmission of personal data to one recipient and the risk of further transmissions to third parties already constituted loss of control; the data subject did not need to prove a feeling of helplessness, fear, or anxiety to be entitled to damages.

### SO Warszawa - III C 904/23

*Source: Regional Court in Warsaw, 2026-02-16 — https://overview.legal/posts/53100 — original: https://gdprhub.eu/index.php?title=SO_Warszawa_-_III_C_904/23*

Facts — The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. Holding — The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

### BGH VI ZR 109/23

*Source: German Supreme Court, 2025-01-28 — https://overview.legal/posts/125638 — original: https://gdprhub.eu/index.php?title=BGH_VI_ZR_109/23*

Facts — The data subject, a private individual, objected to the controller’s processing of their personal data. The controller, a commercial entity, had collected and processed the data subject’s personal data for marketing and profiling purposes. The data subject sent an email to the controller objecting to such a “processing or use” of his data to which the controller failed to respond The data subject claimed that the processing was unlawful and requested its cessation under Article 17(1)(d) GDPR. The data subject claimed that, when he receives messages of this nature, it gives rise to an uneasy feeling that personal data has been disclosed to unauthorized persons, precisely because the data was unlawfully used. The data subject had to deal with unwanted advertising and the origin of the data, creating a quite stressful impression of loss of control. Moreover, the controller initially did not respond after the infringement, which, from the data subject’s perspective, constituted yet another disregard of him. The controller argued that its processing was justified under Article 6(1)(f) GDPR as a legitimate interest. The lower courts had differing views on whether the processing met GDPR standards. Holding — The court stated, that a claim for non-material damages cannot be denied on the grounds that the harm does not exceed a certain severity threshold. However the court found, that the data subject did not sufficiently demonstrate that he suffered non-material damage at all. The court stated that the CJEU had clarified in several judgements that a mere infringement of the provisions of the GDPR is not sufficient to establish a claim for damages; rather, as an independent prerequisite, actual damage (caused by the infringement) must also be demonstrated by the data subject. The court elaborated that once the loss of control is established this itself constitutes the non-material damage, and there is no need for further distinct or additional concerns or anxieties on the part of the data subject. The court held, that in the current case a loss of control could at most be presumed if the controller had made the data subject’s data accessible to third parties when sending the advertising email which the controller did not. The court also held, that where loss of control cannot be established, it suffices for a damages claim that the individual affected demonstrates a well-founded fear that his personal data would be misused by unauthorized third parties as a result of the GDPR infringement. However, the court held that a mere assertion of fear without any proven negative consequences is insufficient, as is a purely hypothetical risk of misuse by an unauthorized third party. The court considered that the data subject had submitted that he fears the controller might also disclose his email address to third parties because the controller has already used it without authorization (vis-à-vis the data subject). However the court held that only those further infringements could, if they occur, give rise to independent claims for damages. Regarding the the controller’s failure to respond to the data subject’s email objecting to the sending of the emails, the court held, that this might at most exacerbate any existing non-material damage, but it does not establish it in the first place.

### Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6

*Source: Court of Justice of the European Union, C-65/23, 2024-12-19 — https://overview.legal/posts/132156 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0065*

In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR regarding Member States' ability to adopt more specific rules for processing employee data in the employment context. The case arose from a dispute between an employee (MK) and his employer (K GmbH) over compensation for non-material damage allegedly caused by the processing of personal data based on a works agreement. The Court held that Article 88 does not grant Member States or social partners a margin of discretion to deviate from the core GDPR requirements of Article 5, Article 6(1), and Article 9, meaning national courts must conduct full judicial review of whether such data processing complies with these fundamental GDPR provisions.

### Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether

*Source: Court of Justice of the European Union, C-507/23, 2024-10-04 — https://overview.legal/posts/132162 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0507*

The Court of Justice of the European Union issued a preliminary ruling on a reference from the Latvian Supreme Court in Case C-507/23, involving an individual ("A") and the Patērētāju tiesību aizsardzības centrs (Consumer Rights Protection Centre, Latvia) regarding compensation for non-material damage allegedly suffered from unlawful processing of personal data under Article 82(1) GDPR. The Court addressed whether apologies can constitute compensation for non-material damage and whether the controller's attitude and motivation may be considered in assessing the form and level of compensation. No fine was imposed, as the ruling clarifies interpretive questions of EU law for the referring national court.

## Guidance

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation

*Source: EDPB, edpb-opinion-202507-epo-adequacydecision-en, 2025-05-06 — https://overview.legal/posts/50823 — original: https://www.edpb.europa.eu/documents/adequacy/opinion-072025-regarding-the-european-commission-draft-implementing-decision_en*

EDPB, Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation, 2025.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

## Enforcement decisions

### UODO (Poland) - DKN.5131.27.2023

*Source: UODO (Poland), 2026-05-19 — https://overview.legal/posts/83471 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.27.2023*

Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information regarding whether certain individuals were subject to mandatory quarantine to prevent and combat the SARS-COV-2 virus. An employee of the controller posted a file containing this information on a private server in November 2020. An automated search engine indexing bot subsequently accessed the file and made its full contents available in search results to any Internet user. The supervisory authority received an electronic report concerning a potential data breach in February 2021. The controller had not notified the DPA or the data subjects of this incident, as it concluded it had not acted as a controller in the context of the processing operations at issue. The DPA launched an investigation into the unauthorised disclosure of personal data and initiated administrative proceedings against the controller in August 2023. Holding — The DPA issued the controller three separate fines amounting to PLN 33,700 (€7,800) in total, as it considered its GDPR violations were the result of three separate courses of conduct. It held that the social welfare unit had clearly determined the means and purposes of processing and acted as controller within the meaning of Article 4(7) GDPR – the employee responsible for the processing operations had acted with the unit’s authorisation, at its instruction, and on its behalf. First, the DPA held the controller had violated Articles 24(1), 25(1), 32(1), and 32(2) GDPR by failing to implement appropriate technical and organisational measures and imposed a fine of PLN 15,000 (€3,460) on the controller. This resulted in violations of the principles of integrity, confidentiality and accountability set out in Articles 5(1)(f) and 5(2) GDPR. There was an internal document in effect during the data breach that identified the risk level of processing as high. However, the DPA pointed out this document did not include, among other things, the number of data subjects, the periods for data storage, and the duration of the processing. The measures implemented were not reviewed or updated and also proved to be ineffective. Second, the DPA issued the controller a fine of PLN 5,500 (€1,270) for an infringement of Article 33(1) GDPR due to a failure to report the data breach to the supervisory authority. Finally, the DPA held that the controller had violated Article 34(1) GDPR by failing to notify the data subjects of the data breach and imposed a fine of PLN 13,200 (€3,060) on the controller. In addition, it ordered the controller to notify the data subjects of the breach in question.

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

### Permanent TSB: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Ireland, 2026-05-08 — https://overview.legal/posts/53597 — original: https://www.enforcementtracker.com/ETid-3146*

Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security.

### Sports association: Insufficient legal basis for data processing

*Source: Polish National Personal Data Protection Office (UODO), 2019-04-25 — https://overview.legal/posts/46159 — original: https://www.enforcementtracker.com/ETid-44*

One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact addresses and PESEL numbers. Meanwhile, there is no legal basis for such a wide range of data on judges to be available on the Internet. By making them public, the administrator posed a potential risk of their unauthorized use, e.g. to impersonate them for the purpose of borrowing or other obligations. Although the associa

### CZECH REPUBLIC DPA: Insufficient technical and organisational measures to ensure information security

*Source: Czech DPA (UOOU), 2019-02-28 — https://overview.legal/posts/46129 — original: https://www.enforcementtracker.com/ETid-14*

Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ('integrity and confidentiality').

### AZOP (Croatia) - Decision 08-03-2022 (energy company)

*Source: AZOP (Croatia), 2026-08-03 — https://overview.legal/posts/184714 — original: https://gdprhub.eu/index.php?title=AZOP_(Croatia)_-_Decision_08-03-2022_(energy_company)*

Facts — The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the refuelling. Consequently, he wanted to exercise consumer protection rights. In this exercise, he requested a copy of the gas station's video surveillance recordings, specifying the date and time of the event. The controller, however, rejected the request on the grounds that there was no written request from the authorities to provide a copy of the recording, that the purpose of the request was not justified, and that obtaining such a copy would adversely affect the rights and freedoms of gas station employees and customers who were there at that moment. The data subject then asked for the DPA's opinion on the matter (and did not yet file a complaint). The DPA published an opinion which stated that the controller had to provide the data subject with copies of the requested video surveillance recording. However, the controller replied to the data subject that they could not provide the requested recording due to fact that they had already destroyed the recordings. The data subject then filed a complaint with the DPA for a violation of Article 15(3) GDPR. Holding — The DPA upheld the complaint. The DPA found that the controller violated Article 15(3) GDPR, by denying him the right to obtain a copy of the video surveillance recording. Hence, the DPA decided to impose a fine on the controller. Regarding the height of the fine, the DPA considered that the controller gained a financial benefit from the violation, since it avoided the financial damage it might have suffered as a result of the consumer dispute with the data subject. The DPA emphasised that it cannot determine whether the data subject is entitled to compensation for damages in his consumer protection dispute. However, the DPA decided to impose a of HRK 940,000 (approx. €120,000), for the violation of Article 15(3) GDPR.

### Provincial Health Authority of Cosenza: Insufficient legal basis for data processing

*Source: Italian Data Protection Authority (Garante), 2020-11-17 — https://overview.legal/posts/46562 — original: https://www.enforcementtracker.com/ETid-447*

Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority, without sufficient legal basis

### T.K. EOOD: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Commision of Bulgaria (KZLD), 2020-02-20 — https://overview.legal/posts/46383 — original: https://www.enforcementtracker.com/ETid-268*

The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to ensure the information security. T.K. EOOD processed the personal data of I.S. unlawfully nine times in duration of five months. The breaches caused damages to the data subject.

## Recent developments

### An analysis of Dutch case law: what factors play a role in awarding (or not) and determining the extent of damages under the GDPR?

*Source: News, 2022-11-17 — https://overview.legal/posts/6245 — original: https://www.vast-online.nl/art/4442/een-analyse-van-de-nederlandse-rechtspraak-welke-factoren-spelen-een-rol-bij-het-al-dan-niet-toekennen-en-vaststellen-van-de-omvang-van-een-schadevergoeding-op-grond-van-de-avg#entry-1349*

Since May 2018, the GDPR has been directly applicable in the European Economic Area, including the member states of the European Union, Liechtenstein, Norway, and Iceland. Four years later, awarding damages for GDPR violations is still not a common practice in the Netherlands, despite the fact that news reports regularly mention data breaches and other GDPR violations. This article analyzes Dutch case law over the past four years to see what factors may influence the awarding of damages under th

### Privacyactivisten waarschuwen tegen het afschaffen van de compensatie voor inbreuken op de bescherming van persoonlijke gegevens.

*Source: EURactiv, 2022-10-13 — https://overview.legal/posts/51834*

De Advocaat-Generaal van het Gerechtshof van de Europese Unie (HvJEU) heeft een niet-bindend advies uitgebracht, waar privacyactivisten zich zorgen over maken, omdat dit de mogelijkheden van gebruikers om hun privacyrechten op te eisen onder de AVG (Algemene Verordening Gegevensbescherming) verder zou kunnen beperken.

Volgens het [advies](https://curia.europa.eu/juris/document/document.jsf;jsessionid=79F0B703F7CD84C2DE01BF340FD03C29?text=&docid=266842&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=244110), dat vorige week is uitgebracht, zouden Europeanen nauwelijks enige compensatie ontvangen als...

### The Court of Justice confirmed that there is no "threshold" for GDPR damages

*Source: noyb - European Center for Digital Rights, 2023-05-04 — https://overview.legal/posts/53241 — original: https://noyb.eu/en/court-justice-confirmed-there-no-threshold-gdpr-damages*

, contrary to national courts. Today, the Court of Justice of the European Union (CJEU) issued the first judgment on emotional damages under the GDPR, confirming that the GDPR does not require a "threshold" for damages. The other demands by the Court are the typical requirements for any damages claim. Press Release by the CJEU Judgment by the CJEU CJEU confirms "emotional damages". The CJEU has confirmed that users have a right to compensation when their personal data was illegally processed. As

### Privacy activists warn against removing compensation for data protection breaches

*Source: EURactiv, 2022-10-13 — https://overview.legal/posts/6258 — original: https://www.euractiv.com/section/data-protection/news/privacy-activists-warn-again-removing-compensation-for-data-protection-breaches/#entry-1043*

> The Advocate General of the Court of Justice of the European Union (CJEU) issued a non-binding opinion, which privacy advocates fear could further limit users’ possibilities to enforce their privacy rights under the GDPR. 

> According to [the opinion](https://curia.europa.eu/juris/document/document.jsf;jsessionid=79F0B703F7CD84C2DE01BF340FD03C29?text=&docid=266842&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid=244110) delivered last week, Europeans would hardly get compensated if t

### Dirkzwager: ABRvS geeft uitleg aan het AVG-begrip "de instelling, uitoefening of onderbouwing van een rechtsvordering"

*Source: Dirkzwager, 2022-10-05 — https://overview.legal/posts/6332 — original: https://www.dirkzwager.nl/kennis/artikelen/abrvs-geeft-uitleg-aan-het-avg-begrip-de-instelling-uitoefening-of-onderbouwing-van-een-rechtsvordering/#entry-968*

> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State

## Literature

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### Civil Liability for Processing of Personal Data in the GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132465 — original: https://doi.org/10.21552/edpl/2019/4/7*

### Latvia ∙ Compensation for Non-Material Damage in the Form of an Apology under the GDPR: Damage from a Viral Video Posted Online

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132582 — original: https://doi.org/10.21552/edpl/2025/3/12*

### The Court of Justice on the Excessiveness of Access Requests under the GDPR

*Source: European Journal of Risk Regulation, 2026-07-09 — https://overview.legal/posts/83502 — original: https://doi.org/10.1017/err.2026.10117*

Abstract This case note comments on the preliminary ruling of the Court of Justice of the EU in Case C-526/24 Brillen Rottler v TC of 19 March 2026, which addresses the abuse of rights under the General Data Protection Regulation (GDPR), specifically in the context of requests for access to personal data under Article 15 GDPR and compensation under Article 82 GDPR. First, the Court held that even a first access request may be regarded as “excessive” where the controller demonstrates that it was

### GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act

*Source: European Data Protection Law Review, 2018-01-01 — https://overview.legal/posts/132478 — original: https://doi.org/10.21552/edpl/2018/3/15*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/aansprakelijkheid · 2026-08-22
